HomeSecurityPowerhouse VPN products used in DDoS attacks

Powerhouse VPN products are used in DDoS attacks

Some botnet operators are abusing VPN servers from VPN provider Powerhouse Management as a way to bounce and amplify unwanted traffic as part of DDoS attacks.

This new DDoS vector has been discovered and documented by a security researcher going online as Phenomite, who shared his findings with ZDNet last week.

The researcher said that the root cause of this new DDoS vector is a service (not yet identified) running on UDP port 20811 on Powerhouse VPN servers.

Powerhouse VPN

Phenomite says that attackers can “ping” this port with a one-byte request, and the service will respond with packets that are up to 40 times the size of the original packet.

Since these packets are UDP-based, they can also be modified to contain a false IP . This means that an attacker can send a single-byte UDP packet to a Powerhouse VPN server, which then amplifies it and sends it to the IP address of a DDoS attack victim – what security researchers call a reflected/amplified DDoS attack.

Both Phenomite and ZDNet have contacted Powerhouse Management to inform the company about the behavior of its products, seeking to ensure that a patch to its servers that will prevent its VPN infrastructure from being abused in future DDoS attacks.

However, the company has not responded to the relevant requests.

Additionally, we also learned today that threat actors have also discovered this DDoS attack vector, which they have already used in real attacks.

According to a scan conducted by Phenomite last week, there are currently around 1,520 Powerhouse servers exposing UDP port 20811, meaning they can be abused by DDoS threat groups.

While the servers are located all over the world, most of the vulnerable systems appear to be "in the UK, Vienna and Hong Kong," the researcher told ZDNet.

Until Powerhouse fixes this leak, the researcher has recommended that companies block any traffic originating from the VPN provider networks (AS21926 and AS22363) or block any traffic where the “srcport” is 20811.

The second solution is recommended, as it does not block legitimate VPN traffic from all Powerhouse VPN users, but only “reflected” packets that are likely part of a DDoS attack.

The Phenomite discovery adds to a long list of new DDoS amplification vectors that have been uncovered in the last three months.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS